* chore: trigger uvai.io production deploy
* feat: UVAI UI/UX full refactor — features page, pricing, Nav, LandingNav (#205)
Zero emoji, real product mockups per feature section, SVG icons everywhere, LandingNav with proper cross-page routing and active states.
Co-authored-by: v0[bot] <v0[bot]@users.noreply.github.com>
* test: improve test coverage, fix Vercel build, dashboard auto-select, E2E resilience (#206)
- 155 new unit tests (middleware, API models, error handling)
- Fix Vercel ERESOLVE build failure via .npmrc legacy-peer-deps
- Fix dashboard ?video= URL param auto-select (issue #159)
- Fix next.config.js duplicate redirects/headers
- Fix CI test dependency installation for Python 3.12
- Make SSE stream always emit terminal pipeline_status event
- Make E2E tests resilient to live server degraded mode
- Replace banned dQw4w9WgXcQ video ID with auJzb1D-fag throughout
* fix: remove hardcoded Grok API key (#194)
🎯 What: Removed the hardcoded fallback value for the GROK_API_KEY in TriModelConsensusTool.
⚠️ Risk: Hardcoded API keys in source code can be exploited if the codebase is exposed or leaked, leading to unauthorized API access, quota exhaustion, and potential financial loss.
🛡️ Solution: Removed the hardcoded string so the tool relies strictly on the environment variable, aligning with secure configuration management practices.
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
* feat(web): add privacy/terms/api-docs/app/login routes; noindex prototype pages (#204)
Resolves 404s on /privacy, /terms, /api/docs, /app, /login and ensures
/prototype carries a noindex robots tag. Scope is intentionally narrow and
does not overlap PR #202 (assets, robots, sitemap, JSON-LD, a11y).
- /privacy, /terms: server-rendered legal placeholder pages with proper
metadata, canonical URLs, and footer links. Plain-language, startup-
friendly; will be replaced before enterprise contracts.
- /api/docs: human-readable reference matching the documentation pointer
returned by /api JSON. Lists actual /api/* routes that exist in code.
- /app, /login: server redirects to /dashboard, marked noindex. UVAI has
no auth gate today, so this matches actual product behavior.
- /prototype: adds a route layout with robots.index=false because the
underlying page is an internal prototype spec, not a public surface.
- LandingFooter: surfaces Privacy and Terms links now that the pages
exist.
Build: next build succeeds, 25 routes generated. Type-check and ESLint clean.
Co-authored-by: Claude <claude@anthropic.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
* test: add unit tests for DatabaseOptimizer._calculate_performance_grade (#182)
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
* fix(security): SECRET_KEY, CORS wildcard, SQL injection, command injection (#207)
Resolves conflicts manually — the conflicting hunks were all in tests/e2e/pipeline.test.ts
and .github/workflows/e2e-tests.yml which were already fixed better in #206.
The security-relevant changes are applied cleanly:
- code_generator.py (#193): replace hardcoded SECRET_KEY with os.getenv/secrets.token_urlsafe
- code_generator.py (#195): restrict CORS allow_origins from ["*"] to localhost origins
- real_api_endpoints.py (#196): read ALLOWED_ORIGINS from env; default to localhost origins
- database_cleanup_service.py (#197): validate table name with regex before SQL use;
quote safe_table_name with double quotes for PRAGMA and DELETE statements
- deployment_manager.py (#200): add path traversal guard (resolve + is_dir check);
add --ignore-scripts to npm install; use resolved_path for all cwd args
- tests/unit/test_database_cleanup_security.py: new unit tests for SQL injection prevention
Closes #193 #195 #196 #197 #200
https://claude.ai/code/session_01AgA9F82EwazbdB5R2f9nsd
Co-authored-by: Claude <noreply@anthropic.com>
* chore: move legacy .agent content under .github (#162)
* chore: move legacy agent files into .github
Agent-Logs-Url: https://github.com/groupthinking/EventRelay/sessions/8e79c6e5-9755-40a2-b8b0-73b9ff75249e
Co-authored-by: groupthinking <154503486+groupthinking@users.noreply.github.com>
* docs: fix relocated agent references
Agent-Logs-Url: https://github.com/groupthinking/EventRelay/sessions/8e79c6e5-9755-40a2-b8b0-73b9ff75249e
Co-authored-by: groupthinking <154503486+groupthinking@users.noreply.github.com>
* docs: remove vague agent rule reference
Agent-Logs-Url: https://github.com/groupthinking/EventRelay/sessions/8e79c6e5-9755-40a2-b8b0-73b9ff75249e
Co-authored-by: groupthinking <154503486+groupthinking@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: groupthinking <154503486+groupthinking@users.noreply.github.com>
* chore(web): UVAI Phase 1 — SEO, a11y, missing static assets
Live uvai.io referenced /favicon.ico, /icon.svg, /apple-touch-icon.png but
apps/web/public/ did not exist in the repo, producing 404s. Layout metadata
also pointed metadataBase and og.url at the legacy v0-uvai.vercel.app host
rather than the canonical uvai.io domain.
Changes:
- Add apps/web/public with favicon.ico (multi-res), icon.svg, apple-touch-icon.png,
og-image.png (1200x630), manifest.json, robots.txt.
- Add apps/web/src/app/sitemap.ts (Next.js Metadata Route sitemap).
- layout.tsx: metadataBase + og.url -> https://uvai.io, add alternates.canonical,
inject Organization/WebSite/SoftwareApplication JSON-LD, add skip-to-main link.
- page.tsx: <main id=\"main\"> as skip-link target.
- LandingNav.tsx: aria-label=\"Primary\" on nav, aria-labels on brand + GitHub
external link, visible focus rings on all interactive elements.
- HeroSection.tsx: focus rings on CTAs, honor prefers-reduced-motion for marquee.
- Add CHANGELOG.md with timestamped entry.
Local verification:
- npx eslint on touched files: clean
- npm run build (apps/web): success, /sitemap.xml route generated, TypeScript clean
No production / deploy / DNS / secret changes.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* chore(web): PR #202 review fixes — no dangerouslySetInnerHTML, MD022, skip-link in layout, central SITE_URL
Addresses code review feedback on PR #202.
1. layout.tsx: replace dangerouslySetInnerHTML JSON-LD with React
<script>{jsonLdString}</script> children. jsonLdString escapes
`<` -> `<` to prevent any nested `</script>` breakout. Build
verified: rendered HTML contains exactly one valid JSON-LD block.
Complies with repo policy that forbids dangerouslySetInnerHTML.
2. CHANGELOG.md: markdownlint MD022 — blank lines after `#### Added`,
`### Changed`, and `### Notes / known follow-ups (not in this change)`.
3. Skip-to-main-content target moved from `apps/web/src/app/page.tsx`'s
<main> to the root layout's content wrapper. The link now works on
every route (dashboard, pricing, features, playground, prototype,
not-found), not just the homepage. Duplicate `id="main"` removed
from page.tsx — rendered HTML on `/` now contains exactly one
`id="main"`.
4. Add apps/web/src/lib/site.ts exporting SITE_URL = 'https://uvai.io'.
layout.tsx (metadataBase, alternates.canonical, og.url, JSON-LD URLs)
and sitemap.ts both consume it. Pricing/playground references kept
as-is — those are mailto: addresses and api.uvai.io examples in
code samples, not the same axis as the site origin.
Failing CI check (E2E Pipeline Tests) is unrelated to this PR:
- E2E runs vitest against BASE_URL=https://uvai.io (the live deployment)
- Live root returns 200 but is stale (title still "UVAI — Video to Software")
- This PR touches zero files under tests/e2e/, src/youtube_extension/,
or apps/web/src/app/api/
- Resolution requires a redeploy of the current main, which is outside
this PR's scope per the original instructions
Local verification:
- npx eslint on touched files: clean (exit 0)
- npm run build (apps/web): ✓ Compiled, TypeScript clean, 21 pages
- Rendered HTML inspection: JSON-LD block present and well-formed;
id="main" present on /, /pricing, /features, /dashboard, /playground;
exactly one id="main" on each prerendered page (no duplicates)
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: v0[bot] <v0[bot]@users.noreply.github.com>
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Claude <claude@anthropic.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Claude Code <claude-code@anthropic.com>
🎯 What: Removed the hardcoded
SECRET_KEYfrom the code generator template insrc/youtube_extension/backend/code_generator.py.SECRET_KEYexposes any generated application directly to potential attackers because the identical key would be generated for every output.🛡️ Solution: Updated the code generator to inject the standard
osandsecretsmodules and define the secret key asSECRET_KEY = os.getenv("SECRET_KEY", secrets.token_urlsafe(32))instead of a static string. This ensures the generated code relies on environment variables or securely randomized keys by default.PR created automatically by Jules for task 13171754861581372920 started by @groupthinking